The deadline for existing Zimbabwean data controllers to appoint a Data Protection Officer was 12 December 2024. The initial deadline for obtaining a data controller licence was 12 March 2025. From 1 September 2026, the Postal and Telecommunications Regulatory Authority of Zimbabwe began mandatory compliance inspections.
This means the Zimbabwe data protection deadline has not been extended. Organisations that have not appointed a qualified Data Protection Officer, notified POTRAZ or obtained the required licence are already late. The immediate priority is to regularise the organisation’s position and prepare evidence that its data protection controls work in practice.
Key Takeaways
- The Data Protection Officer appointment deadline was 12 December 2024 for existing data controllers.
- The initial data controller licensing deadline was 12 March 2025.
- POTRAZ began mandatory compliance inspections on 1 September 2026.
- A person cannot become a compliant DPO through appointment alone. POTRAZ-approved certification is required.
- Schools, healthcare providers, financial institutions, mines, churches, NGOs and public bodies are among the first sectors targeted for inspection.
- Failure to appoint a DPO can result in a level 7 fine, imprisonment for up to two years, or both.
What is the Zimbabwe data protection deadline in 2026?
There is no new September 2026 grace period. The legal deadlines arose from the Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, published as Statutory Instrument 155 of 2024.
The regulations were gazetted on 13 September 2024. Existing data controllers were given 90 days to appoint a Data Protection Officer and notify the Data Protection Authority. That period ended on 12 December 2024.
Existing data controllers were also given six months to submit their licence applications. That deadline fell on 12 March 2025.
POTRAZ’s Regulatory Notice No. 2 of 2026 did not create another deadline. It announced that mandatory inspections and assessments would begin on 1 September 2026.
| Requirement | Applicable date | Current position |
|---|---|---|
| Appoint and notify a Data Protection Officer | 12 December 2024 | Deadline passed |
| Apply for a data controller licence | 12 March 2025 | Deadline passed |
| POTRAZ mandatory inspections begin | 1 September 2026 | Enforcement has started |
| Report a personal data breach | Within 24 hours of awareness | Ongoing obligation |
| Notify affected people of a high-risk breach | Within 72 hours | Ongoing obligation |
| Renew a data controller licence | At least three months before expiry | Licence-specific |
Businesses should therefore stop treating 1 September as a future target. As of September 2026, the inspection risk is already active.
Who must appoint a Data Protection Officer in Zimbabwe?
A licensable data controller in Zimbabwe must appoint a Data Protection Officer and notify POTRAZ. A data controller is the person or organisation that decides why personal data will be collected, what information will be collected and how it will be processed.
This definition covers far more than technology companies.
An employer becomes a data controller when it collects identity details, employment histories, bank information, next-of-kin details and payroll records. A school processes information about learners, parents and employees. A clinic processes identity, contact and health information. A retailer may hold customer names, telephone numbers, delivery addresses and payment records.
An organisation can be a data controller even if it does not sell personal information. Commercial gain is only one of the grounds that can make processing licensable. Deciding the purpose or method of collecting personal data can be sufficient.
The first phase of POTRAZ inspections covers:
- Financial institutions
- Insurance companies
- Local authorities
- Healthcare providers
- Mining enterprises
- Religious organisations
- Schools, tertiary institutions and professional bodies
- Government ministries, departments and agencies
- Non-governmental organisations and private voluntary organisations
These sectors process large volumes of identity, financial, health, employment or children’s information. However, businesses outside these sectors should not assume that the law does not apply to them.
The licence schedule begins with Tier 1, covering between 50 and 1,000 data subjects. Organisations processing information for fewer than 50 people should obtain written guidance before treating themselves as exempt. The definition of a data controller is broader than the licence tier table.
What qualifications must a Zimbabwean DPO have?
A Zimbabwean Data Protection Officer must have relevant expertise, understand the organisation’s operations and complete a certification course approved by POTRAZ. Giving an existing employee the DPO title without assessing their competence and certification does not complete the obligation.
Under SI 155 of 2024, a DPO may have qualifications, skills or experience in:
- Data science
- Data analytics
- Information security systems
- Information systems auditing
- Law
- Auditing
- Another relevant discipline
- Zimbabwean data protection laws and practices
- The organisation’s operations and data-processing activities
Every appointed DPO must also undergo a certification course approved by the Data Protection Authority. The organisation should retain the appointment letter, certification evidence, job description, reporting line and proof that POTRAZ was notified using Form DP2.
The DPO is not simply an IT support officer. The role includes monitoring compliance, handling requests from POTRAZ and data subjects, advising employees, supporting data protection impact assessments, raising awareness, training staff and conducting internal compliance audits.
The officer must be able to perform these responsibilities independently. Management remains responsible for compliance. Appointing a DPO does not transfer the organisation’s legal accountability to one employee.
A practical DPO reporting structure should give the officer direct access to senior management. It should also avoid situations where the same person approves risky data-processing decisions and then audits those decisions without independent oversight.
What will POTRAZ inspect from 1 September 2026?
POTRAZ inspections are expected to test whether an organisation can demonstrate compliance, not merely produce a licence receipt. Inspectors can assess licensing, DPO appointment, security controls, breach procedures and how the organisation manages personal information.
Management should be ready to produce evidence covering the following areas:
| Compliance area | Evidence management should prepare |
|---|---|
| Data controller licensing | Valid licence, application documents and payment evidence |
| DPO appointment | Appointment letter, Form DP2 notification and certification |
| Data inventory | List of personal data held, its purpose and storage location |
| Privacy notices | Notices issued to customers, employees, website users and other subjects |
| Lawful processing | Consent records, contracts or another applicable legal basis |
| Security controls | Access controls, backups, passwords, physical security and risk assessments |
| Data breaches | Incident register and a documented 24-hour escalation procedure |
| Third parties | Contracts with payroll providers, software vendors, consultants and cloud services |
| Cross-border transfers | Records of data transferred or accessed outside Zimbabwe |
| Children’s information | Guardian consent and data protection impact assessments |
| Staff awareness | Attendance registers and evidence of data protection training |
A privacy policy downloaded from the internet is not enough. The documents must describe what the organisation actually does.
For example, an organisation using overseas cloud software must understand where its information is hosted, who can access it and whether personal data is being transferred outside Zimbabwe. Its contracts and privacy notices should reflect that arrangement.
If your organisation has a licence application, DPO appointment or privacy policy sitting unfinished, the inspection risk is already live. Book a Zimbabwe data protection compliance review with M&J Consultants. We test your position against SI 155, identify missing evidence and give management a prioritised remediation plan before the regulator has to find the gaps.
What are the penalties for missing the DPO deadline?
Failure to appoint a Data Protection Officer can result in a fine not exceeding level 7, imprisonment for up to two years, or both. More serious licensing and data-security offences can attract a level 11 fine, imprisonment for up to seven years, or both.
The regulations create separate risks for different failures. These include:
- Processing licensable personal information without a licence
- Failing to renew a data controller licence
- Providing false information in an application
- Failing to appoint a DPO
- Failing to protect personal data
- Failing to report a data breach within the prescribed period
- Failing to comply with other data controller obligations
Businesses should not convert statutory fine levels into a fixed US dollar figure without checking the prevailing legal schedule. Zimbabwe’s monetary framework can change, while the offence level stated in the regulations remains the legally relevant reference.
The commercial consequences may also extend beyond the statutory penalty. A compliance failure can delay tenders, damage relationships with banks and institutional customers, expose weak cybersecurity controls and reduce confidence among employees and clients.
The common objection is that these requirements are expensive for small organisations. That concern is understandable, especially where training and systems must be funded. However, cost pressure does not remove the obligation. The better response is to determine the organisation’s correct tier, avoid unnecessary expenditure and implement the highest-risk controls first.
How should a late organisation regularise its position?
A late organisation should act immediately, document every corrective step and avoid making false claims about its current compliance status. Starting the process does not erase the missed deadline, but it places the organisation in a stronger position than continued inaction.
Management should take the following steps:
- Confirm whether the organisation is a data controller. Review how the business collects employee, customer, supplier, patient, learner or member information.
- Count the data subjects. Count distinct individuals, not the number of spreadsheets or transactions. This determines the appropriate licensing tier.
- Map the personal data. Record what is collected, why it is required, where it is stored, who can access it, how long it is retained and where it is transferred.
- Apply for the correct licence. Submit Form DP1 with the supporting information and prescribed fees.
- Appoint a suitable DPO. Assess the individual’s qualifications, independence, operational knowledge and certification position.
- Notify POTRAZ. Use Form DP2 and retain evidence that the notification was delivered.
- Close the operational gaps. Implement privacy notices, breach procedures, staff training, access controls, supplier agreements and data-subject request processes.
- Prepare an inspection file. Keep the licence, DPO records, policies, risk assessments and supporting evidence in one controlled compliance file.
A pending application should never be presented as an approved licence. Similarly, a person enrolled for training should not be described as certified until certification has been completed. Where the position is unclear, obtain written guidance from POTRAZ and retain the correspondence.
Worked example: A private school in Harare
Consider a Harare private school with 420 learners, 520 parents or guardians and 55 employees. If these are distinct individuals, the school already processes information relating to approximately 995 data subjects before counting applicants, former learners, suppliers and website enquiries.
The school is likely to fall within Tier 1 initially. However, its total could move into Tier 2 once all current and historical records are counted.
The school holds names, addresses, birth certificates, photographs, medical information, academic results, fee records and employment information. It is processing both children’s data and sensitive information. That creates obligations beyond completing a licence form.
The school should appoint and notify a qualified DPO, map its information, document parental consent where required and conduct appropriate data protection impact assessments. It must also control access to learner records, secure paper files and prepare a breach response procedure.
If a staff member mistakenly emails learner records to the wrong parent, the school must assess the incident immediately. Where it constitutes a reportable breach, the 24-hour notification period does not wait for the next management meeting.
This example shows why data protection is a governance issue. It affects operations, human resources, IT, legal compliance and senior management.
Conclusion
Zimbabwe’s data protection enforcement period has begun. The DPO appointment deadline passed on 12 December 2024, the initial licensing deadline passed on 12 March 2025, and POTRAZ inspections started on 1 September 2026.
Appointing someone in name only will not solve the problem. The organisation needs the correct licence, a qualified and certified DPO, documented controls and evidence that personal information is being handled lawfully and securely.
The next action is simple: establish the organisation’s current compliance position before responding to an inspection request.
Book a DPO and data-controller compliance review with M&J Consultants. Bring your current licence, privacy documents and list of business systems. We will show you what is compliant, where the exposure sits and what must be corrected first. The initial output is a scoped gap report, allowing management to decide which actions can be completed internally.
Frequently Asked Questions
Was 1 September 2026 the DPO appointment deadline in Zimbabwe?
No. The deadline for existing data controllers to appoint a Data Protection Officer was 12 December 2024. The date of 1 September 2026 marked the beginning of mandatory POTRAZ compliance inspections. Organisations without the required appointment are therefore already late.
Does every Zimbabwean company need a Data Protection Officer?
Every organisation that qualifies as a licensable data controller must appoint a DPO. A company may be a data controller if it determines why and how employee, customer, supplier or other personal data is collected and processed. Businesses should assess their activities instead of relying only on company size.
Does employee information count as personal data?
Yes. Names, identity numbers, contact details, employment histories, bank information, payroll records, medical information and next-of-kin details are personal data. An employer processing this information is carrying out regulated data-processing activities even if it has no external customer database.
Can an IT manager be appointed as the DPO?
An IT manager may be considered if the person has the required expertise, understands Zimbabwe’s data protection law, completes approved certification and can operate independently. The organisation must also assess conflicts between the person’s operational IT decisions and their responsibility to monitor those decisions.
How does a business notify POTRAZ of its DPO?
The data controller should notify POTRAZ in writing using Form DP2. The organisation should retain the submitted form, delivery evidence, appointment letter and the officer’s certification records. Changes to the DPO’s contact details, resignation or dismissal must also be reported within the prescribed period.
How long is a Zimbabwe data controller licence valid?
A data controller licence is valid for 12 months. The renewal application must be submitted at least three months before the licence expires. Obtaining the first licence is therefore not a once-off exercise. Renewal dates should be included in the organisation’s compliance calendar.


